
EC-CouncilSOC Essentials
Domain 6Objective 4
Dealing with False Positive Alerts SCE Practice Questions (Page 4)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 16–20
- 16
A SOC analyst is triaging an alert that indicates a user account was used to log in from two different countries within 30 minutes. The analyst checks the user's travel history and finds that the user is on a business trip and has a connecting flight that could explain the two locations. The analyst also checks the VPN logs and sees that the user connected through a VPN endpoint in the second country. How should the analyst classify this alert?
Select an answer first - 17
A SOC team notices that a specific detection rule generates a high number of false positives after a recent network infrastructure change. The rule was designed to detect lateral movement by flagging connections to administrative shares (e.g., ADMIN$). After the change, a legitimate backup system now connects to administrative shares on all servers. The team wants to reduce false positives while maintaining detection of lateral movement. Which action is most appropriate?
Select an answer first - 18
In security monitoring, which definition best describes a false positive alert?
Select an answer first - 19
What is the most effective way to use feedback from false positive investigations to improve detection mechanisms?
Select an answer first - 20
What is a primary operational impact of a high volume of false positive alerts on a security operations center (SOC)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.